There is a Ransomware Armageddon Coming for Us All

11/01/2024 0 Comments 0 tags

Generative AI will enable anyone to launch sophisticated phishing attacks that only Next-generation MFA devices can stop The least surprising headline from 2023 is that ransomware again set new records

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

11/01/2024 0 Comments 0 tags

A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid,

New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems

11/01/2024 0 Comments 0 tags

Cybersecurity researchers have developed a proof-of-concept (PoC) code that exploits a recently disclosed critical flaw in the Apache OfBiz open-source Enterprise Resource Planning (ERP) system to execute a memory-resident payload. The vulnerability in question

Threat Actors Increasingly Abusing GitHub for Malicious Purposes

11/01/2024 0 Comments 0 tags

The ubiquity of GitHub in information technology (IT) environments has made it a lucrative choice for threat actors to host and deliver malicious payloads and act as dead drop resolvers, command-and-control,

Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager

11/01/2024 0 Comments 0 tags

A security flaw has been disclosed in Kyocera’s Device Manager product that could be exploited by bad actors to carry out malicious activities on affected systems. “This vulnerability allows attackers to coerce

Why Public Links Expose Your SaaS Attack Surface

11/01/2024 0 Comments 0 tags

Collaboration is a powerful selling point for SaaS applications. Microsoft, Github, Miro, and others promote the collaborative nature of their software applications that allows users to do more. Links to

Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe

11/01/2024 0 Comments 0 tags

Poorly secured Microsoft SQL (MS SQL) servers are being targeted in the U.S., European Union, and Latin American (LATAM) regions as part of an ongoing financially motivated campaign to gain

Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware

11/01/2024 0 Comments 0 tags

A threat actor called Water Curupira has been observed actively distributing the PikaBot loader malware as part of spam campaigns in 2023. “PikaBot’s operators ran phishing campaigns, targeting victims via its two

CISA Flags 6 Vulnerabilities – Apple, Apache, Adobe , D-Link, Joomla Under Attack

11/01/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability

Microsoft’s January 2024 Windows Update Patches 48 New Vulnerabilities

11/01/2024 0 Comments 0 tags

Microsoft has addressed a total of 48 security flaws spanning its software as part of its Patch Tuesday updates for January 2024. Of the 48 bugs, two are rated Critical and 46